Text Widget oEmbed Security & Risk Analysis

wordpress.org/plugins/text-widget-oembed

Allows oEmbed and the [embed] shortcode to be used in sidebar text widgets.

30 active installs v1.0 PHP + WP 2.9+ Updated May 24, 2011
oembedshortcodeshortcodessidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Text Widget oEmbed Safe to Use in 2026?

Generally Safe

Score 85/100

Text Widget oEmbed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "text-widget-oembed" plugin v1.0 exhibits a remarkably strong security posture. The absence of any identified entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the attack surface. Furthermore, the code demonstrates excellent practices with zero dangerous functions, all SQL queries using prepared statements, and 100% of output properly escaped. The lack of file operations, external HTTP requests, and critically, the absence of nonce and capability checks, while appearing as potential weaknesses, are mitigated by the plugin's minimal interaction points and lack of dynamic data processing, suggesting a very simple and contained functionality.

Vulnerabilities
None known

Text Widget oEmbed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Text Widget oEmbed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Text Widget oEmbed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterwidget_texttext-widget-oembed.php:11
filterwidget_texttext-widget-oembed.php:12
Maintenance & Trust

Text Widget oEmbed Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedMay 24, 2011
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Text Widget oEmbed Developer Profile

Daisy Olsen

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Text Widget oEmbed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Text Widget oEmbed